{"record":"BeyondTrust evidence record","url":"https://nexalign.io/vendors/beyondtrust","vendor":{"slug":"beyondtrust","name":"BeyondTrust","domain":"beyondtrust.com","category":"pam","categoryLabel":"Privileged access management"},"lastChecked":"2026-07-28T10:18:14.307Z","coverage":{"earliest":"2020-03-18T14:18:50.000Z","latest":"2026-07-28T10:18:14.307Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":52,"kindsOfSource":5,"attributedAdvisories":12,"knownExploited":1,"registerEntriesNotAttributable":24,"practitionerThreads":0,"independentItems":9,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":29,"latest":"2026-07-06T16:13:42.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":7,"latest":"2026-07-06T17:16:31.143Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":6,"latest":"2026-07-08T07:11:45.053Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":1,"latest":"2026-02-13T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":9,"latest":"2026-07-28T10:18:14.307Z"}],"advisories":{"shown":6,"total":12,"truncated":true,"fullList":"https://nexalign.io/vendors/beyondtrust/advisories","items":[{"id":"CVE-2026-1731","description":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2026-02-13T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-1731","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5559"]},{"id":"WID-SEC-2026-2215","description":"Affected products: BeyondTrust Remote Support, BeyondTrust Privileged Remote Access","severity":"high","cvss":8.1,"knownExploited":false,"date":"2026-07-08T07:11:45.053Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2215"]},{"id":"CVE-2026-40141","description":"A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters.","severity":"critical","cvss":9.9,"knownExploited":false,"date":"2026-07-06T17:16:31.143Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-40141","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41889"]},{"id":"CVE-2026-40140","description":"BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem.","severity":"high","cvss":7.5,"knownExploited":false,"date":"2026-07-06T17:16:31.030Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-40140","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41888"]},{"id":"CVE-2026-40139","description":"A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support.","severity":"critical","cvss":9.8,"knownExploited":false,"date":"2026-07-06T17:16:30.920Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-40139","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41887"]},{"id":"CVE-2026-40138","description":"A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access.","severity":"critical","cvss":8.1,"knownExploited":false,"date":"2026-07-06T17:16:30.793Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-40138","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41886"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":5,"total":9,"truncated":true,"items":[{"title":"BeyondTrust Reviews, Ratings & Features 2023 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/operational-technology-security/vendor/beyondtrust","date":null},{"title":"BeyondTrust - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/BeyondTrust","date":null},{"title":"BeyondTrust Reviews, Ratings & Features 2025 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/it-security/vendor/beyondtrust","date":null},{"title":"BeyondTrust Customer Reviews 2025 | Privileged Access Management","host":"softwarereviews.com","url":"https://www.softwarereviews.com/products/beyondtrust","date":null},{"title":"BeyondTrust Remote Support Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/beyondtrust-remote-support-reviews","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 24 register entries mention BeyondTrust without naming a product of BeyondTrust as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming BeyondTrust was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}